The new docs.trellix.com offers a modernized UI and AI-powered features like conversational searches. Content is currently available only in English. Other languages will be available in mid-October 2026. We hope you enjoy the new experience.

Trellix Endpoint Security (ENS) 26.8 - Release Notes - Linux

Prev Next

Rating

The rating defines the urgency for installing this update.

This release is recommended for all environments. Apply this update at the earliest convenience.

For more information, see KB51560

New features and enhancements

  • Customizable log file paths from CLI - You can now define a custom directory for product log files from the command-line interface.

    Note

    By default, the software stores logs in /var/McAfee/ens/log/

  • Bundle 6900 Anti-Malware Scan Engine - This release includes the 6900 Anti-Malware Scan Engine. The engine uses a Native Standard Template Library (STL) for improved performance and detection capabilities. This update modernizes core components to ensure better system compatibility and security posture.

  • Support for new distribution - This release introduces official compatibility for Ubuntu 26.4, Debian 13, and AlmaLinux 10.2.

    Note

    On Ubuntu 26.04, ensure that you install apt-utils before deploying Trellix Endpoint Security (ENS) for Linux .

    apt-get install -y apt-utils

  • Extended Kernel Compatibility - This release adds compatibility for new kernels on Ubuntu 24.04 and Ubuntu 25.04. See Updated platform, environment, or operating system support for the complete list.

Resolved issues

Reference

Resolution

ESFL-8484

ENSL caused servers to stop responding during shutdown. Failures occurred when exploit prevention or access protection were active. Excessive event queuing during deregistration caused high system load. The software now disables the hook during deregistration. Disabling the hook ensures stability.

ESFL-8220

Resolved an issue where adaptive rules for ENSL did not appear in Trellix ePO - On-prem. The property translator task for the Firewall failed to process these rules. This failure occurred due to malformed JSON data. ENSL now uses correct data types for physical medium properties. These changes ensure rules translate correctly and appear in the console.

Known issues

For a list of current known issues in Threat Prevention, see Trellix Knowledge Base article KB87518.

For a list of current known issues in Firewall, see Trellix Knowledge Base article KB91327.

Note

Before upgrading Trellix Endpoint Security (ENS) for Linux Firewall, see Trellix Knowledge Base article 000014500.

Updated platform, environment, or operating system support

This release includes additional kernel support. You can get the latest information about supported platforms, environments, and operating systems from the following links:

  • Trellix Endpoint Security (ENS) for Linux Threat Prevention 26.x from KB87073

  • Trellix Endpoint Security (ENS) for Linux Firewall 26.x from KB91326

This release supports these additional kernel modules:

  • Ubuntu 24.04

    • 6.17.0-14-generic

    • 6.17.0-19-generic

    • 6.17.0-20-generic

    • 6.14.0-37-generic

    • 6.17.0-22-generic

    • 6.17.0-23-generic

    • 6.17.0-29-generic

    • 6.17.0-35-generic

    • 6.17.0-40-generic

    • 6.17.0-1013-aws

    • 7.0.0-14-generic

  • Ubuntu 25.04

    • 6.14.0-37-generic

  • Ubuntu 26.04

    • 7.0.0-15-generic

  • Debian 13

    • 6.12.38+deb13-amd64

  • AlmaLinux 10.2

    • 6.12.0-211.30.1.el10_2.x86_64

Additional information

On Intel architecture, you must have installed Trellix Agent 5.6.4 (Build Number 110) (64-bit) or later to use this software.

On ARM architecture, you must have installed Trellix Agent 5.8.3 (Build Number 622) (64-bit) or later to use this software.